# Syslog + Beats

**URL:** <https://discuss.elastic.co/t/syslog-beats/43048>\
**Category:** Logstash\
**Created:** [February 29, 2016, 8:41pm UTC](https://discuss.elastic.co/t/syslog-beats/43048 "2016-02-29T20:41:59Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![matthieurobin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/matthieurobin/32/8161_2.png) [@matthieurobin](https://discuss.elastic.co/u/matthieurobin)\
**Post date:** [February 29, 2016, 8:41pm UTC](https://discuss.elastic.co/t/syslog-beats/43048/1 "2016-02-29T20:41:59Z")

</div>

Hello guys,

I'm currently configuring my ELK cluster to receive syslog from ESXi and Winlogbeats events from Windows.

On input file, i got:

```
input {
  udp {
    port => 3514
    type => "syslog"
      }
  beats {
    port => 5044
	type => "wineventlog"
  }
}

```

And output file:  
output {  
if [type] == "wineventlog" {  
elasticsearch {  
hosts =\> ["[http://localhost:9200](http://localhost:9200)"]  
index =\> "%{[@metadata][beat]}-%{+YYYY.MM.dd}"  
document\_type =\> "%{[@metadata][type]}"  
}  
}  
else {  
elasticsearch {  
hosts =\> ["[http://localhost:9200](http://localhost:9200)"]  
index =\> "syslog-%{+YYYY.MM.dd}"  
}  
}   
stdout { codec =\> rubydebug }

```
}

```

Is it correct to got 2 different index?  
Is there a better way?

Thanks in advance for your help.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [February 29, 2016, 8:47pm UTC](https://discuss.elastic.co/t/syslog-beats/43048/2 "2016-02-29T20:47:15Z")

</div>

You _could_ use different index series, but it's not necessary and as you add more kinds of logs you'll quickly end up with many indexes. Each shard of an index has a fixed memory overhead so you don't want too many of them.

I don't recommend using `[@metadata][beat]` as part of the index name you won't have control over which index series are created, plus a misconfiguration could cause a big mess.

---

<div class="post-metadata">

**Author:** ![matthieurobin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/matthieurobin/32/8161_2.png) [@matthieurobin](https://discuss.elastic.co/u/matthieurobin)\
**Post date:** [February 29, 2016, 8:54pm UTC](https://discuss.elastic.co/t/syslog-beats/43048/3 "2016-02-29T20:54:28Z")

</div>

> [@matthieurobin](#):
>
> output { if [type] == "wineventlog" { elasticsearch { hosts =\> ["[http://localhost:9200](http://localhost:9200)"]

Thanks a lot for your help!  
so, this output is enough?  
output {  
elasticsearch {  
hosts =\> ["[http://localhost:9200](http://localhost:9200)"]  
}  
stdout { codec =\> rubydebug }

}

Do I have to configure the "type" in the input?

Thanks in advance.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [February 29, 2016, 10:17pm UTC](https://discuss.elastic.co/t/syslog-beats/43048/4 "2016-02-29T22:17:45Z")

</div>

Using a different index does keep data structure clean though. You can put things into different indices, just shard accordingly - ie don't use 5 shards, start with 1!

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 1, 2016, 9:17pm UTC](https://discuss.elastic.co/t/syslog-beats/43048/5 "2016-03-01T21:17:43Z")

</div>

> Do I have to configure the "type" in the input?

Yes, that'a a good idea nevertheless.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:09am UTC](https://discuss.elastic.co/t/syslog-beats/43048/6 "2017-07-06T05:09:02Z")

</div>


